[Snort-users] Snort Advisory - integer underflow issue

Steve Kane steve.kane at ...1935...
Thu Jan 11 17:25:59 EST 2007


An integer underflow issue has been reported in the experimental GRE 
protocol decoder.  This could present a potential vulnerability or cause 
the Snort process to fail. This issue should affect a small minority of 
users, because it only exists for users who:

1. Download Snort source code from releases 2.6.1, 2.6.1.1, or 2.6.1.2

AND

2. Configure the build using the --enable-gre option, to enable the
experimental GRE protocol decoder

This issue does not exist for users who do not meet both of these 
conditions.

A fix for the issue is in the Snort 2.6.1 development branch.  Users who
have built Snort with --enable-gre are advised to recompile Snort 
without the --enable-gre feature, or check out the code from the 2.6.1 
branch and rebuild it with the --enable-gre feature. Thanks to Chris 
Rohlf of Calyptix Security for reporting the issue.





More information about the Snort-users mailing list